Mechanism · Model identity attestation

Launch-state attestation does not by itself cover weights loaded later

On this page

← All known flaws

SignificantTheoretical argumentMitigated

Attestation measures launch state, and weights are read from disk after boot. A signature checked at load time does not stop a malicious hypervisor from altering the disk afterwards 1. Tinfoil reports mitigating this with dm-verity checks on every read 1. Unmeasured runtime configuration remains a general risk 6.

Sources: [1] · [6]

Search

Full search page